Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
24.475 exploits
Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Magic Value Type Confusion
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISCO
abrir ↗Exploit-DB
ERPnext 11 - Cross-Site Scripting
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RISCO
abrir ↗Exploit-DB
MakeMyTrip 7.2.4 - Information Disclosure
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISCO
abrir ↗Exploit-DB
ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all
23RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86/x64) - vbscript Code Execution
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISCO
abrir ↗Exploit-DB
Schneider Electric PLCs - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10
23RISCO
abrir ↗Exploit-DB
D-Link DSL-3782 - Authentication Bypass
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0
28RISCO
abrir ↗Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 4.8.0 < 4.8.0-46 - AF_PACKET packet_set_ring Privilege Escalation (Metasploit)
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DynoRoot DHCP Client - Command Injection
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir ↗Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISCO
abrir ↗Exploit-DB
Powerlogic/Schneider Electric IONXXXX Series - Cross-Site Request Forgery
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RISCO
abrir ↗Exploit-DB
Intelbras NCLOUD 300 1.0 - Authentication bypass
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins CLI - HTTP Java Deserialization (Metasploit)
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISCO
abrir ↗Exploit-DB
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISCO
abrir ↗Exploit-DB
Inteno IOPSYS 2.0 < 4.2.0 - 'p910nd' Remote Command Execution
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques
28RISCO
abrir ↗Exploit-DB
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability
28RISCO
abrir ↗Exploit-DB
Rockwell Scada System 27.011 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISCO
abrir ↗Exploit-DB
VirtueMart 3.1.14 - Persistent Cross-Site Scripting
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RISCO
abrir ↗Exploit-DB
2345 Security Guard 3.7 - '2345NsProtect.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser
23RISCO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.